NEWS

Crypto CEO Accuses North Korea of Stealing $387 Million From Bitget Platform

Bitget CEO Gracy Chen says North Korean hackers stole $387.5 million via a wallet system breach; a $464M User Protection Fund will cover losses.

Dylan H.

News Desk

September 26, 2026
6 min read
Crypto CEO Accuses North Korea of Stealing $387 Million From Bitget Platform

Bitget CEO Blames North Korea for $387.5 Million Wallet Breach

Bitget CEO Gracy Chen said on September 25, 2026, that state-sponsored hackers linked to North Korea stole approximately $387.5 million from the Singapore-based cryptocurrency exchange after breaching its backend wallet infrastructure. Chen said the platform's User Protection Fund — which holds more than $464 million — will be used to cover the full amount, so no user deposits are expected to be permanently lost.


Incident Summary

FieldDetails
PlatformBitget (Singapore-based crypto exchange)
Amount Stolen$387.5 million
Assets TakenETH, XRP, USDC, and other cryptocurrencies
Attributed ToNorth Korea (CEO cites links to Lazarus Group)
Reimbursement FundUser Protection Fund
Fund SizeOver $464 million
Attribution StatusCompany claim; independent government confirmation not yet issued

How the Theft Reportedly Happened

Initial Breach and Escalation

According to Chen, attackers first compromised roughly $175 million before the theft escalated to a total of $387.5 million as investigators continued tracing unauthorized outflows. Bitget said the intrusion targeted its backend wallet services systems, with hackers exploiting vulnerabilities there to enable transfers that were not authorized by the platform.

Assets Drained

The stolen funds spanned multiple cryptocurrencies, including ETH, XRP, and USDC, suggesting the attackers had broad access across several wallet pools rather than a single isolated hot wallet.

Emergency Response

Bitget suspended withdrawals platform-wide while it investigated the scope of the breach and worked to trace and, where possible, freeze the stolen assets before they could be laundered through mixers or cross-chain bridges — a standard early-stage response for exchanges hit by large-scale wallet compromises.


The North Korea Attribution: Evidence and Confidence Level

What Bitget Says Points to the DPRK

Chen and Bitget's investigators pointed to a combination of IP addresses, behavioral patterns, and on-chain transaction signatures they say match those associated with North Korean state-sponsored hacking groups. Blockchain analysts working the case reportedly identified overlaps with techniques used in past Lazarus Group operations, the umbrella threat actor long tied to Pyongyang's cryptocurrency-theft campaigns.

Investigators Involved

Bitget said it engaged outside security firms, including Mandiant and SlowMist, to assist with forensic analysis of the breach. Chen stated the company has "notified relevant authorities and are cooperating fully with them globally," indicating law enforcement agencies have been looped into the investigation.

How Confident Is This Attribution?

It is important to note this attribution is currently Bitget's own claim, corroborated by blockchain forensic patterns rather than a confirmed government determination. No U.S. Treasury, FBI, or South Korean government statement had been issued attributing the theft to North Korea at the time of publication. On-chain and infrastructure indicators consistent with Lazarus Group / TraderTraitor-style tradecraft are a strong signal given the group's long history of targeting crypto platforms, but formal attribution typically takes weeks as investigators complete wallet-tracing and infrastructure analysis.


The User Protection Fund and What It Means for Users

Bitget said its User Protection Fund, which holds more than $464 million, will be used to make affected users whole, fully covering the $387.5 million loss. The fund functions as a self-insurance reserve exchanges maintain specifically to absorb losses from hacks, exploits, or operational failures without directly touching customer-held assets outside the compromised wallets.

To aid recovery of the stolen funds, Bitget said it is offering:

  • A 5% bounty to any platform that voluntarily freezes funds traced back to the theft
  • An additional 5% bounty for parties that assist in the successful recovery of stolen assets

Withdrawals remained suspended as of publication while the platform completes its security review, meaning users could face short-term access delays even though the company maintains no funds will be permanently lost.


North Korea's Pattern of Crypto-Platform Theft

If confirmed, this incident would extend a well-documented pattern: North Korea has been repeatedly linked to some of the largest cryptocurrency heists in history, with analysts tracking DPRK-linked cyber operations estimating the regime stole more than $2 billion through crypto theft in the past year alone, and over $3 billion cumulatively since 2017. Proceeds from these operations are widely assessed by international investigators to help fund North Korea's sanctioned weapons and missile programs, making crypto exchanges a persistent, high-value target for Pyongyang's state-sponsored hacking units.


Impact Assessment

Impact AreaDescription
User FundsExpected to be fully covered by the User Protection Fund; no anticipated permanent loss to depositors
Platform AvailabilityWithdrawals suspended during the investigation, delaying user access to funds
Reputational RiskAdds Bitget to a growing list of exchanges targeted by DPRK-linked actors in 2026
Sector-Wide ScrutinyLikely to renew regulatory pressure on exchange hot-wallet and backend wallet-service security
GeopoliticalReinforces evidence of North Korea's continued reliance on crypto theft to fund state programs

Recommendations

For Exchanges and Custodians

Audit backend wallet service architecture for privilege-escalation paths, enforce multi-party computation (MPC) or hardware-backed signing for high-value transfers, and implement real-time anomaly detection on outbound wallet transactions. Segment wallet infrastructure so a single service compromise cannot cascade into transfers across multiple asset pools.

For Bitget Users

  • Monitor official Bitget channels only — do not click links in unsolicited emails or social media messages referencing this incident
  • Be alert for phishing campaigns that impersonate Bitget support offering "priority reimbursement" or asking for wallet credentials
  • Confirm any communication about fund status through Bitget's verified app or website before taking action

For Security Teams and Blockchain Analysts

  • Track and flag wallet addresses associated with the stolen funds as they move through exchanges, mixers, and bridges
  • Share indicators of compromise with industry partners given the suspected Lazarus Group / TraderTraitor nexus
  • Treat this incident as a reminder to review internal wallet-service access controls against known DPRK TTPs

Key Takeaways

  1. Bitget CEO Gracy Chen says North Korean state-sponsored hackers stole $387.5 million by exploiting the exchange's backend wallet services.
  2. The theft escalated from an initial $175 million before reaching its final total, spanning ETH, XRP, USDC, and other assets.
  3. Attribution to North Korea rests on IP addresses, behavioral patterns, and on-chain signatures resembling Lazarus Group tradecraft — a strong but not yet government-confirmed determination.
  4. Bitget's $464 million User Protection Fund is expected to fully cover the loss, with withdrawals temporarily suspended during recovery.
  5. Bitget is offering 5% bounties for voluntary fund freezing and for assistance recovering stolen assets.
  6. The incident fits North Korea's broader, well-documented pattern of targeting cryptocurrency platforms to fund state programs, with estimated cumulative theft exceeding $3 billion since 2017.

Sources